Your network contains a server named Server1 that runs Windows Server 2012 R2. Server1
has the Active Directory Certificate Services server role installed and is configured as a
standalone certification authority (CA).
You install a second server named Server2. You install the Online Responder role service
on Server2.
You need to ensure that Server1 can issue an Online Certificate Status Protocol (OCSP)
Response Signing certificate to Server2.
What should you run on Server1?
A.
The certreq.exe command and specify the -policy parameter
B.
The certutil.exe command and specify the -getkey parameter
C.
The certutil.exe command and specify the -setreg parameter
D.
The certreq.exe command and specify the -retrieve parameter
aaaa
C. The certutil.exe command and specify the -setreg parameter
certutil -v -setreg policy\EnableRequestExtensionList +1.3.6.1.5.5.7.48.1.5
https://technet.microsoft.com/en-us/library/cc732526.aspx